On-Device Control Flow Verification for Java Programs

Arnaud Fontaine 1 Samuel Hym 1 Isabelle Simplot-Ryl 1
1 POPS - System and Networking for Portable Objects Proved to be Safe
LIFL - Laboratoire d'Informatique Fondamentale de Lille, Inria Lille - Nord Europe, IRCICA
Abstract : While mobile devices have become ubiquitous and generally multi-application capable, their operating systems provide few high level mechanisms to protect services offered by application vendors against potentially hostile applications coexisting on the device. In this paper, we tackle the issue of controlling application interactions including col- lusion in Java-based systems running on open, constrained devices such as smart cards or mobile phones. We present a model specially designed to be embedded in constrained devices to verify on-device at loading- time that interactions between applications abide by the security policies of each involved application without resulting in run-time computation overheads; this model deals with application (un)installations and policy changes in an incremental fashion. We sketch the application of our ap- proach and its security enhancements on a multi-application use case for GlobalPlatform/Java Card smart cards.
Type de document :
Communication dans un congrès
International Symposium on Engineering Secure Software and Systems (ESSoS 2011), Feb 2011, Madrid, Spain. Springer, 6542, pp.43--57, 2011, Lecture Notes in Computer Science
Liste complète des métadonnées

https://hal.inria.fr/inria-00562611
Contributeur : Isabelle Simplot-Ryl <>
Soumis le : jeudi 3 février 2011 - 16:22:27
Dernière modification le : jeudi 11 janvier 2018 - 06:22:13

Identifiants

  • HAL Id : inria-00562611, version 1

Collections

Citation

Arnaud Fontaine, Samuel Hym, Isabelle Simplot-Ryl. On-Device Control Flow Verification for Java Programs. International Symposium on Engineering Secure Software and Systems (ESSoS 2011), Feb 2011, Madrid, Spain. Springer, 6542, pp.43--57, 2011, Lecture Notes in Computer Science. 〈inria-00562611〉

Partager

Métriques

Consultations de la notice

81